CVE-2021-24942

CVE-2021-24942: Menu Item Visibility Control <= 0.5 - Admin+ Arbitrary PHP Code Execution

Vendor Unknown
Product Menu Item Visibility Control
Published December 26, 2022
Last update April 14, 2025

CVSS base score

What the vulnerability does

01Description

The Menu Item Visibility Control WordPress plugin through 0.5 doesn't sanitize and validate the "Visibility logic" option for WordPress menu items, which could allow highly privileged users to execute arbitrary PHP code even in a hardened environment.

Key dates

02Disclosure timeline

December 26, 2022 CVE published
April 14, 2025 Record updated